Service IAM Roles in Production Accounts
Veeam Backup for AWS launches worker instances in production accounts to perform the following operations:
- EFS indexing.
- [Applies if you enable worker deployment in production accounts in the backup policy or restore settings] Creating EC2 image-level backups and performing restore from EC2 image-level backups.
By default, Veeam Backup for AWS selects the most appropriate network settings of AWS Regions in production accounts to launch worker instances used to perform EFS indexing operations, and the default network settings of AWS Regions to launch worker instances used to perform EC2 backup and restore operations. However, you can add worker configurations to specify network settings for each region in which worker instances will be deployed. When creating new worker configurations, Veeam Backup for AWS uses Worker Configuration IAM roles only to list network settings available in AWS Regions of production AWS accounts. To learn how to add worker configurations, see Adding Configurations for Production Accounts.
Worker Configuration IAM Role Permissions
If you add specific worker configurations that will be used to launch worker instances in production accounts, consider that IAM roles specified in the worker configuration settings must be granted the following permissions: